216.73.217.22

CVE-2025-58357

· Published 04/09/2025 10:42 · Modified 04/09/2025 15:35

Labels: CVE-2025-58357 2025-09-04CVE-2025-58357CWE-79[email protected]

Essential information

Published
04/09/2025 10:42
Modified
04/09/2025 15:35
Author
Creator
CVSS
9.6 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CVSS metrics

Description

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 contains a vulnerability in the chat page's script gadgets that enables content injection attacks through multiple vectors: malicious prompt injection pages, compromised MCP servers, and exploited tool integrations. This is fixed in version 0.14.0.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
5ire / 5ire cpe:2.3:a:5ire:5ire:0.13.2:*:*:*:*:*:*:*
5ire / 5ire cpe:2.3:a:5ire:5ire:0.14.0:*:*:*:*:*:*:*

References